Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-71988: MSI Radix AXE6600 Router Firmware v781521 Allows Remote Command Execution

CVE-2026-71988 · published 26 days ago
Summary

The MSI Radix AXE6600 router's firmware has a security flaw that lets hackers send commands to the device from anywhere. This can allow them to take control of the router and access sensitive information. We recommend updating the firmware to the latest version to fix this issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
msi radix axe6600 <= v781521
Original advisory text
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device...
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Severity
9.3 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 1%
Type
CWE-78OS Command Injection
Timeline
Published9 Aug 2026
Updated30 Aug 2026
First seen9 Aug 2026
Sources
CVE-2026-71988 · MITRE
Monitor software like this
Free during beta